DOC-018 ← Document Portal

Physical and Environmental Security

Security zones, access control, server room, CCTV and clean desk
Document Number
DOC-018
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ Facility Manager / CISO
Approved by
▸ Board / CEO
Legal Basis
Art. 21(2) NIS2; ISO/IEC 27001:2022 A.7.1–A.7.14
Related Documents
DOC-008 | DOC-010

1. Physical Security Zones

The organisation designates the following physical security zones:

ZoneDescriptionExample locationsAccess
Zone 1 – Public Areas accessible to visitors without restriction Reception lobby, external conference room Unrestricted; CCTV monitoring
Zone 2 – Office Employee work areas Open-plan offices, internal meeting rooms Card / PIN code; visitors with escort
Zone 3 – Restricted Areas with restricted access for selected employees IT rooms, comms cabinets, archives Card + PIN or biometrics; authorised persons list
Zone 4 – Critical Server room, MDF/IDF with key systems Main server room, OT/ICS rack Card + PIN + (optional biometrics); entry log; CCTV; max. 2 authorised persons
▸ Organisation completes – zone mapping

Security zone map (building plan): ▸ [plan location / Annex A]

Number of locations covered by policy: ▸ [number of addresses]

2. Physical Access Control

MechanismZoneRequirementImplementation in organisation
Access card system 2, 3, 4 Required ▸ [e.g. HID / Lenel / proprietary system]
Entry log 3, 4 Required, retention ▸ 12 monthsmin. 12 months – NIS2 ▸ [automatic from card system]
CCTV / video surveillance 1, 2, 3, 4 Required, recording retention ▸ min. 30 daysmin. 30 days ▸ [e.g. Hikvision / Axis; retention: X days]
Airlock / man-trap 4 (server room) ▸ [Required / Recommended] ▸ [available / planned / not applicable]
Visitor escorting 2, 3 Required – visitors must not move unescorted ▸ [visitor register at reception, visitor badge]

3. Server Room Requirements (Zone 4)

ParameterRequirementImplementation / value
Room temperature ▸ 18–27°CASHRAE Class A1 ▸ [precision air conditioning – make/model]
Relative humidity ▸ 40–60%per ASHRAE ▸ [monitoring: YES / NO]
UPS (power backup) ▸ min. 15 min at full loadmin. 15 min ▸ [make/model, backup time: X min]
Generator ▸ [Required / Recommended] ▸ [available – start-up time: X sec / planned / not applicable]
Fire detection Required ▸ [smoke detectors / VESDA / suppression system (Novec/FM200)]
Flood detection Recommended ▸ [flood sensors under raised floor: YES / NO]
Power redundancy ▸ [min. A+B or 2N]recommended for critical systems ▸ [dual PSU in servers: YES / NO]
Environmental monitoring (temp/humidity/power) Required – 24/7 alerts ▸ [monitoring tool, e.g. APC / Paessler PRTG]

4. Clean Desk and Screen Policy

  • When finishing work or leaving your workstation: all confidential documents locked in drawer or safe.
  • Screen lock after ▸ [5 minutes]max. 15 min of inactivity or before leaving desk.
  • No media (USB, drives, printouts) left on desk unattended.
  • Paper document shredding: shredder of at least class ▸ [DIN P-4]min. DIN P-4 for confidential data.
  • Multifunction devices (printers): printouts collected immediately; confidential documents printed only at the printer (PIN release mode).

Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0▸ Initial release▸ Board
DOC-018 Physical and Environmental Security | v1.0 | NIS2/ISMS